VendorsNetWinsurgeftp2.0c
Vulnerabilities

NetWin SurgeFTP 2.0c

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2001-1356
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
Published 2002-06-11 · Modified
10.0EPSS 0.038
CVE-2013-4742
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
Published 2013-08-09 · Modified
7.5EPSS 0.042
CVE-2004-2318
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.
Published 2005-08-16 · Modified
5.0EPSS 0.019